Following the Shells: From Ghost Seoul to PandaChina
A compromised website does not always end with a defacement, a ransom note, or stolen data. Sometimes, the real value is simply keeping the door open and selling the key.
Web shells make that possible. Planted on compromised servers, they can provide attackers with continued remote access, allowing them to interact with files and systems long after the initial intrusion. In underground markets, that access has become a commodity of its own. Sellers advertise compromised websites, administrative panels and webshell access to buyers who may have had no involvement in breaching the target in the first place. Some accesses are sold individually, while others are packaged by the hundreds, turning compromised infrastructure into inventory.
One seller operating in this space is Ghost Seoul, a Telegram-based operation advertising webshell access across a surprisingly broad range of targets. Government agencies, educational institutions, commercial organizations and other websites appeared among its listings, with prices varying according to the access being offered. On the surface, there was little to distinguish Ghost Seoul from the many sellers competing in the same underground economy.
But looking beyond the latest advertisements revealed a different story. Historical Telegram records on StealthMole showed that the identity visible today was only one part of a longer trail. Older usernames, archived messages and connections between seemingly separate accounts and channels gradually pushed the investigation further back, raising questions about how long the operation had really been active and who had been behind it before the name Ghost Seoul appeared.
This report follows that trail, starting with a webshell market active in 2026 and working backward through the digital traces its operator left behind. What emerged was not simply a snapshot of another Telegram seller, but a history that had been hiding behind changing names.
Where the Trail Began
Ghost Seoul first drew attention through a Telegram channel built around a straightforward business: selling access to websites that had already been compromised. Throughout July 2026, the channel advertised webshell and root-shell access across a broad mix of targets, from commercial websites and universities to government and defence-related domains. Alongside individual listings, the operator also offered webshells in bulk, suggesting that compromised access was being treated less as the outcome of individual attacks and more as inventory for resale.
- https://t.me/web******r
The listings followed a fairly consistent pattern. A domain would be posted alongside a price and, in some cases, details about the level of access being offered. On July 21, for example, the channel advertised 100 “fresh & clean” webshells for $70, an offer that appeared again on July 25, 26 and 27. Individual domains were priced separately, with listings ranging from relatively low-cost website access to several hundred dollars for more notable targets. Some posts were later updated to indicate that the advertised access had been sold.
The targets themselves made the channel difficult to dismiss as just another small webshell shop. South Korean government domains including seoul.go.kr and busan.go.kr appeared alongside Germany's bmvg.de, the UN Food and Agriculture Organization's fao.org, and Singapore's Ministry of Defence domain, mindef.gov.sg. The mindef.gov.sg listing was particularly notable: Ghost Seoul advertised what it described as root shell access for $200 on July 25, before marking the access as sold three days later. These posts document what the seller claimed to possess and sell; they do not, by themselves, independently verify the compromise or transaction.
There were signs that the operation was not limited to simply posting whatever access happened to become available. Listings appeared repeatedly throughout the month, bulk packages were offered alongside individual domains, and the channel included targets spanning multiple countries and sectors. Taken together, the activity presented Ghost Seoul as an active participant in the market for compromised web infrastructure rather than a channel focused on a single campaign or target set.
The listings also provided the first lead beyond the channel itself. Across multiple posts, interested buyers were directed to @c******es to arrange purchases, while @web*****r was repeatedly presented as the channel or proof point for the operation. The same pattern appeared in bulk advertisements, including posts that instructed buyers to “DM @c******es” while pointing them back to Ghost Seoul for proof. Rather than being an occasional mention, @c******es appeared consistently at the point where an advertised shell or access was expected to turn into a transaction.
At that stage, we knew what Ghost Seoul was selling and had a direct contact used by the operation, but very little about the person behind it. That made @c******es the natural next pivot. Instead of looking at another advertised domain, we searched the account itself through StealthMole's historical Telegram records.
One Account, Many Names
The first account worth following was @c******es. Ghost Seoul repeatedly directed interested buyers to this handle, while the account itself left little ambiguity about what it was connected to: its Telegram bio listed “DOMAIN MARKET: Web*****r.” Rather than treating the username as a permanent identity, the investigation pivoted on the account's underlying Telegram identifier, User ID 8423162304.
That distinction quickly became important. StealthMole's historical Telegram indexing showed that the account visible as COVID77 / @c******es in July 2026 had appeared under a series of different identities during the preceding months. At least eight name and username combinations were captured across the available snapshots, including:
- Panda / @panda******0x
- PANDA0X / @panda****0x
- PANDA/X1ON / @panda****0x
- Panda/Cod3r / @panda***0x
- THE/PANDA / @panda****a0x
- Panda/PANDA / @panda***0x
- JiuPanda / @x*****panda
- COVID77 / @c******es
The names changed, but Telegram User ID 8423162304 remained the common identifier. This was significant because @x***npanda and @Panda*****0x had already surfaced elsewhere during searches for Ghost Seoul-related material. Initially, those appearances could have been interpreted as other users circulating or promoting the seller's advertisements. Historical indexing showed otherwise: the Panda, x***npanda and COVID77 identities were different snapshots of the same Telegram account.
The account's activity also remained concentrated around the webshell trade despite the changing names. StealthMole associated User ID 8423162304 with only four observed Telegram communities, one being the Ghost Seoul channel. Three were explicitly centered on the sale or exchange of webshell and server access, while the fourth, Indonesia Defacer, placed the account within another community closely adjacent to that activity.
- https://t.me/ma***tweb***l
- https://t.me/WebshellCpan*****S
- https://t.me/IndonesiaD*****r
This also changed the meaning of earlier messages uncovered during the investigation. In the Webshell / Cpanel / Smtp / Rdp channel, a user appearing as JiuPanda / @x***npanda had circulated Ghost Seoul material. The same Telegram User ID later appeared as Panda / @Panda*****0x in INDONESIA DEFACER | WEBSHELL MARKET. What had initially looked like separate accounts promoting the same seller could now be followed back to User ID 8423162304.
Even the visual identity evolved without completely abandoning the theme. The July @c******es account used imagery closely resembling Ghost Seoul's profile branding, while the channel itself leaned heavily into a South Korean persona through the Korean flag, Seoul imagery and the words “KOREA CYBER UNIT.” The historical records, however, showed that this presentation came after months of Panda-branded identities. The Korean branding therefore provides useful context about how the operation presented itself at that point in time, but it cannot establish where the operator was actually located or their nationality.
That raised a different question: what had PandaChina been doing before Ghost Seoul appeared?
Before Ghost Seoul
Once the historical identities behind Telegram User ID 8423162304 were established, the earlier Panda-era messages could be viewed in a different light. They were no longer references to another seller who happened to circulate Ghost Seoul material. They were part of the same account's earlier activity, and that activity showed that selling compromised web access had begun well before the Ghost Seoul name appeared.
Under @Panda*****0x, the account was already advertising webshells and other forms of server access through Telegram in March 2026. The posts followed a commercial format that would later remain familiar: lists of available domains, prices, payment instructions and direct contact details. Buyers were offered payment through BTC, USDT, Ethereum and DOGE, while advertisements directed them to @Panda*****0x to complete a purchase. Some posts also pointed users toward another contact point, @Pandam******0x, for additional information.
The scale of the inventory was visible in PRICELIST23.txt, a file circulated by the account containing a long list of access points across multiple countries. Many entries included URLs using port 2083, alongside educational and other domains from countries including Peru, Bolivia, Colombia, India, Pakistan, Nepal, Bhutan, Nigeria and Indonesia. Elsewhere, the seller advertised access individually and in bulk, showing that the later Ghost Seoul model of turning compromised infrastructure into priced inventory was already present during the Panda period.
Some of the earlier advertisements also reached government infrastructure. In one March post, @Panda*****0x was listed as the contact for access involving domains such as apd.lacounty.gov, lcc.nebraska.gov, jakarta.bps.go.id, sanjuandelrio.gob.mx, poderjudicialchiapas.gob.mx, dprf.gov.br, and pn-jambi.go.id. Individual prices were attached to the listings, while some entries were subsequently marked as sold. The same message directed users to @Pandam******0x for further information, placing that handle alongside the Panda-era sales activity.
One listing provided a closer look at what was being offered. The account advertised bandungkota.bps.go.id as “shell access” for $100, with @Panda*****0x listed as the contact. An accompanying image showed what appeared to be an active Hidden Shell Version 3.0.2 interface carrying ALFA TEAM branding. The screen displayed server and filesystem information, including the path /datos/www/bandungkota/images/, as well as an Apache/PHP environment and functionality for interacting with files on the host. As with the later Ghost Seoul listings, the screenshot reflects evidence presented by the seller and should not be treated as independent verification that the advertised access remained valid at the time of observation.
The Panda operation also used a separate space for credibility and sales proof. Advertisements from @Panda*****0x directed buyers to the private Telegram invite:
- https://t.me/+VPB*******NTM1
The link was described as a “Proofs Channel,” and its Telegram preview identified it as Panda Shells. One of the associated messages combined the invite with the seller's payment options and direct contact:
- DM: @Panda*****0x
- Proofs Channel: @t.me/+VPB***********NTM1
Another identifier, @panda***x, also appeared in text associated with the Panda Shells channel. At this stage, however, the available evidence does not establish what role that account played, so it remains an associated artifact rather than an attributed identity.
Overall, the Panda-era records push the observable webshell activity back months before the current Ghost Seoul branding. The names and presentation changed, but the underlying business was already recognizable: compromised access was advertised, priced, marked as sold, supported by proof material and promoted through dedicated Telegram channels.
The private Panda Shells link also gave the investigation somewhere new to go. Unlike a username that could change, the same invite began appearing in messages posted by other sellers, opening a path from the history of one account into the wider market operating around it.
Following the Market Around Panda
The Panda Shells invite offered a useful pivot because it was not confined to messages from @Panda*****0x. Searching the same private Telegram link across StealthMole surfaced it in other webshell-related activity, suggesting that the sales infrastructure around Panda extended beyond a single public account.
One of those appearances came from jacky27 / @ja*****7, Telegram User ID 7595948503. Messages associated with the account advertised webshell and cPanel access while pointing buyers toward the same private channel previously promoted by @Panda*****0x:
- https://t.me/+VP************NTM1
This was a more meaningful overlap than two sellers simply appearing in the same Telegram group. During the Panda period, User ID 8423162304 had explicitly described the invite as its “Proofs Channel.” Finding @ja*****7 directing users toward that same destination connected the account to infrastructure already associated with Panda's sales activity.
The overlap, however, does not tell us exactly what that relationship was. @ja*****7 could have been another seller using a shared proof channel, a reseller working from the same inventory, someone cooperating with Panda, or simply a user republishing existing advertisements. The available evidence does not establish common ownership of the two Telegram accounts, so User ID 7595948503 remains a separate actor rather than another Panda alias.
Another contact surfaced repeatedly as the investigation moved through these webshell communities: @os*******e. Earlier searches for web*****r had already captured posts from an account appearing as C0L1N / @os*******e, Telegram User ID 6767763093. In one message, buyers were instructed:
- Pm: @os*******e
- Channels & Support: @web*****r
Other material placed the same account around Panda-era sales. A message attributed to Os/M1d / @os*******e, for example, advertised access to carnalprime.cl, quaorealty.com, carverdentallab.dev.tqnia.me and vermione.cz, but ended by directing buyers to:
- PM: @Panda*****0x
- CH: @Pandam******0x
The relationship also appeared in the opposite direction. On March 19, StealthMole captured C0L1N forwarding material originating from Ghost Seoul channel ID 3512450200, while the resulting advertisement used @os*******e as the direct contact and @web*****r as the channel. Rather than two completely separate sales footprints, the records showed C0L1N appearing around both the earlier Panda infrastructure and the later Ghost Seoul operation.
That pattern is significant, but it has limits. Nothing found so far establishes that User IDs 6767763093 and 8423162304 were controlled by the same person, nor does the overlap prove that C0L1N was formally part of Ghost Seoul. What the records do show is repeated commercial crossover: advertisements, contact points and channels associated with one seller appearing in activity involving the other.
Keeping those distinctions mattered, particularly with @os*******e, because unlike most of the surrounding accounts, his Telegram profile exposed an artifact that could be followed outside Telegram altogether: a phone number.
The C0L1N Pivot
The phone number attached to @os*******e offered something the other Telegram artifacts had not: a lead that could be followed outside the webshell channels themselves. Searching the account in StealthMole showed that C0L1N was no longer active under its observed identity, with the Telegram account currently deleted, but historical snapshots preserved enough information to continue tracing it.
The account was anchored to Telegram User ID 6767763093. In a March 8, 2026 snapshot, StealthMole recorded it as:
- Name: C0L1N
- Username: @os*******e
- Telegram User ID: 6767763093
- Phone: 18**********90
- Bio: col1n has return
Like the primary Ghost Seoul account, C0L1N's Telegram identity had not remained static. Historical records captured at least three username or profile-name changes during March 2026 alone, while hundreds of messages associated with the account revolved around webshells and related access sales. The profile itself used Brazilian-themed imagery, including the country's flag, but there was no evidence to treat that branding as an indication of the operator's actual location or nationality.
The more useful artifact was 18**********90. Rather than stopping at the Telegram profile, the number was searched against StealthMole's compromised-data holdings, where it appeared across seven leaked files. This shifted the investigation away from what C0L1N chose to publish on Telegram and toward identifiers that had appeared alongside the same number elsewhere.
Several of those records were then examined through MoleChat to identify useful correlations without manually working through each dataset. One recurring association linked the phone number to the numeric identifier 30*****61 and the corresponding QQ email address:
- 30********1@qq.com
The finding was useful, but it was not enough to put a real-world name behind C0L1N. The leaked records establish an association between 18**********90 and 30********1@qq.com; they do not establish who was controlling either identifier during the webshell activity observed in 2026.
Conclusion
Ghost Seoul initially appeared to be a relatively straightforward Telegram operation selling webshell and server access. Following the account behind those listings, however, showed that the identity visible in July 2026 was only the latest part of a longer history.
The most important thread throughout the investigation was not a username, but the underlying Telegram User ID. While names shifted from Panda and x***npanda identities to @c******es, User ID 8423162304 allowed activity separated by months, different handles and different Telegram communities to be connected back to the same account. That history showed that the commercial activity associated with Ghost Seoul had roots in an earlier Panda-branded webshell operation, where compromised access was already being priced, advertised and supported through dedicated sales and proof channels.
Following those older artifacts also exposed a wider marketplace around the account. The private Panda Shells channel, @Pandam******0x, @ja*****7 and @os*******e showed how advertisements and contact points moved between sellers and webshell-focused communities. Those overlaps do not establish a single organized group behind the accounts, but they do show that Ghost Seoul operated within an interconnected trading environment rather than in isolation. The C0L1N branch pushed that trail beyond Telegram altogether, linking User ID 6767763093 to phone number 18**********90 and, through leaked records, to QQ identifier 30*****61 and 30********1@qq.com. The trail ended there, without enough evidence to identify the person behind the account.
There are still important questions the available data cannot answer. The investigation does not establish the real-world identity or location of the Ghost Seoul operator, despite the operation's prominent Korean branding. It also does not reveal how the advertised systems were initially compromised, who purchased the access, or what buyers subsequently did with it. Likewise, listings marked as sold remain claims made by the seller rather than independent confirmation of successful transactions.
What the investigation does establish is a traceable history behind an identity that, viewed only in its current form, would have appeared much newer and more isolated. Ghost Seoul was where the trail began, but the account's earlier footprints showed that it was not where the story started.
Editorial Note
Attribution in underground ecosystems is rarely absolute. Usernames change, infrastructure is shared, and associations do not always imply common ownership. This investigation shows how StealthMole's historical records and cross-source pivots can help navigate that uncertainty, connecting activity across changing identities while keeping the line between what the evidence establishes and what remains unknown.
To access the unmasked report or full details, please reach out to us separately.
Contact us: support@stealthmole.com
Labels: Featured, Threat Actor